CVE-2023-26203: Fortinet Fortinac

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A use of hard-coded credentials vulnerability [CWE-798] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions may allow an authenticated attacker to access to the database via shell commands.

Affected products

  • Fortinet Fortinac: from 8.7.0, up to and including 9.2.7; from 9.4.0, before 9.4.3 (fixed in 9.4.3)
  • Fortinet Fortinac-F: version 7.2.0 only

Published 2023-05-03. Last modified 2026-06-17.